Microsoft is extending a lifeline to businesses relying on Windows Server 2016 as the platform edges closer to its end of support. With the introduction of Azure Arc-enabled Extended Security Updates (ESUs), organizations can now secure critical security patches without the necessity of migrating their legacy servers to Azure.
As the countdown to the end of extended support for Windows Server 2016 approaches on January 12, 2027, organizations that have not yet upgraded can opt for ESUs, which will provide essential security updates until January 2030. This offering is particularly beneficial for businesses that require additional time to transition their critical applications without exposing their systems to potential security vulnerabilities.
“Extended Security Updates give you access to Critical and Important security updates for Windows Server 2016 for up to three years after end of support, covering January 12, 2027 through January 2030. They provide a supported bridge for business-critical applications that need more time to migrate, without new features or non-security fixes, and without leaving systems exposed while you plan your move,” Microsoft explained.
Pay-as-you-go pricing offers flexible ESU coverage
This innovative service allows organizations to enroll their Windows Server 2016 instances linked via Azure Arc, ensuring they receive ESUs without the need to shift workloads to Azure virtual machines. The flexibility extends to on-premises servers, edge environments, and other cloud platforms, enabling administrators to maintain security for legacy workloads while strategizing their modernization efforts.
Microsoft emphasizes a simplified, cloud-based experience with direct enrollment through Azure, centralized administration, and the elimination of traditional activation-key requirements. The flexible pay-as-you-go pricing model allows organizations to acquire coverage as needed, avoiding the constraints of long-term contracts.
By enrolling servers in ESUs through Azure Arc, organizations also unlock access to a suite of Azure management capabilities, including Azure Update Manager, Change Tracking and Inventory, and Azure Policy Guest Configuration. These tools enhance visibility, compliance, and operational management across hybrid and multicloud environments.
How IT admins can prepare for Windows Server 2016 ESUs
For IT administrators looking to implement Extended Security Updates (ESUs) via Azure Arc, the first step is to identify eligible Windows Server systems that are nearing or have reached their end of support. Connecting these systems to Azure Arc is crucial. Once onboarded, Azure Arc facilitates a centralized approach to enroll servers in ESUs, monitor coverage, and manage update compliance without the reliance on traditional activation keys. Microsoft advises ensuring that servers are configured to receive updates through Windows Update, Windows Server Update Services (WSUS), or Azure Update Manager.
It is important for businesses to view ESUs as a temporary solution rather than a permanent fix. This extended timeframe should be utilized to modernize applications and strategize migrations to supported platforms, ensuring a seamless transition into the future of their IT infrastructure.